MacOsSandboxBackend class final

The macOS backend: SBPL profile generation plus sandbox-exec wrapping.

Implemented types

Constructors

MacOsSandboxBackend({String workspaceRoot = '/workspace', String tmpdir = '/tmp', Map<String, String> envVars = const {}})
Creates the backend bound to a run's context. The defaults exist for bare display/backends-picked-outside-a-run; kernel execution always passes the real workspace, tmpdir and injected env.
const

Properties

enforces → bool
Whether this backend actually confines at the OS level. false means wrapCommand is a passthrough and kernel mode degrades to the Dart policy layers.
no setteroverride
envVars → Map<String, String>
The cube's injected environment variables (hidden vars excluded).
final
hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
tmpdir → String
Writable scratch directory handed to the child as TMPDIR.
final
workspaceRoot → String
The real writable root (the env cwd) — HOME inside the sandbox.
final

Methods

buildProfile(CubeSpec spec, {required String workspaceRoot}) → String
The profile content for spec. workspaceRoot is the real writable root (the env cwd); the cube's /workspace is realized as that cwd.
override
buildSandboxProfile(CubeSpec spec, {String? workspaceRoot}) → String
Renders spec as an SBPL profile.
describe() → String
override
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited
wrapCommand(String command, {required String profilePath, Map<String, String> env = const {}}) → String
Wraps command so it runs inside the OS sandbox. profilePath names the content-verified profile file staged by the shell (<home>/.fah/cube-profiles/); implementations that confine by other means may ignore it. env carries the caller's per-exec environment (ShellExecOptions.env): kernel wrapping must thread it into the clean child environment or session vars and secrets are silently dropped — entries override the backend's cube-bound vars. Implementations that change nothing may ignore it too.
override

Operators

operator ==(Object other) → bool
The equality operator.
inherited